> For the complete documentation index, see [llms.txt](https://docs.cipp.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cipp.app/user-documentation/identity/reports/risk-detections.md).

# Risk Detections

This report lists the risk detections Microsoft Entra ID Protection has raised, with the most recent first. Each row is a single detection rather than a user, so one account under investigation may appear several times with different detection types and timings.

## Table Details

The properties returned are for the Graph resource type `riskDetection`. For more information on the properties please see the [Graph documentation](https://learn.microsoft.com/en-us/graph/api/resources/riskdetection?view=graph-rest-beta#properties).

{% hint style="info" %}
The **Location** column is a button rather than plain text. Selecting it opens a Location Details dialog plotting the detection on a map, with the city, state and country listed alongside, which is usually the quickest way to judge whether a detection is a genuine anomaly or the user travelling.
{% endhint %}

## Filters

| Filter                | Shows                                                                                                     |
| --------------------- | --------------------------------------------------------------------------------------------------------- |
| Users at Risk         | Detections still open and not yet acted on.                                                               |
| Confirmed Compromised | Detections an administrator has confirmed as a genuine compromise.                                        |
| Confirmed Safe        | Detections an administrator has marked as legitimate activity.                                            |
| Remediated            | Detections resolved by the user meeting a remediation requirement, such as a self-service password reset. |

## Table Actions

<table><thead><tr><th>Action</th><th>Description</th><th data-type="checkbox">Bulk Action Available</th></tr></thead><tbody><tr><td>Research Compromised Account</td><td>Opens the <a data-mention href="/pages/EGPbyWqFtAVEtdgnFb5i">/pages/EGPbyWqFtAVEtdgnFb5i</a> tab for the account the detection relates to, where the usual indicators of compromise are gathered in one place.</td><td>false</td></tr><tr><td>More Info</td><td>Opens the Extended Info flyout with the full details for the selected row.</td><td>false</td></tr></tbody></table>

{% hint style="info" %}
Risk state is held against the user rather than the individual detection, so marking a user as safe or compromised in Entra ID Protection changes the state shown on every detection for that account. The [Risky Users](/user-documentation/identity/administration/risky-users.md) page is where a user's overall risk is reviewed and dismissed.
{% endhint %}

{% hint style="warning" %}
Entra ID Protection needs Entra ID P2 licensing to report detections in full. Tenants without it see limited or no detection data, so an empty table means the feature is unavailable rather than that no risk was detected.
{% endhint %}

***

## Feature Requests / Ideas

We value your feedback and ideas. Please raise any [feature requests](https://github.com/CyberDrain/CIPP/issues/new?template=feature.yml) on GitHub.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cipp.app/user-documentation/identity/reports/risk-detections.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
